
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@activeprospect/integration-components
Advanced tools
A Vue component library for LeadConduit integrations.
[!IMPORTANT]
This branch,vue2
, is a long-lived branch intended to facilitate development of versions of this library which depend on Vue2 and Vue3 simultaneously.Vue3 is used in the LeadConduit app, and required by the ui-components library; However, since many of our integrations with a Rich UI depend on this library, maintaining a non-breaking version pinned to a Vue2 dependency is important for continuity and ease of development.
Future work should focus on the
master
branch, which is tied to Vue3. If new versions of this library need to be released with a Vue2 dependency, you must select thevue2
branch when running the "Publish to npm registry" GitHub Action
In your integration's rich UI (RUI) code, add these components inside the <script>
tag of your .vue
files:
<script>
import { Navigation } from '@activeprospect/integration-components';
// etc.
And then the components can be used in the <template>
:
<section> etc. </section>
<Navigation :onNext="save"></Navigation>
Run Storybook to see them all, and their detailed docs.
Navigation
- footer with navigation (Next, Prev, Finish, & Cancel)To test, run npm run storybook
in one window, and npm run cypress:run
in another.
This library uses the following technologies:
All Vue components are stored in /src/components.
To make sure each Vue component is picked up by Rollup, it must be added to the /src/index.js
file like so:
export { default as Navigation } from './Navigation.vue';
Rollup bundles our Vue components for distribution. The Rollup config file is located in /build.
To run Rollup and build the Vue components, simply run npm run build.
This will take all the Vue components listed in /src/index.js
and compile them, outputting the result into /dist.
Storybook is used as a development and documentation framework. To read more on Storybook, you can find their docs here. Storybook stories are stored in /src/stories
, and the Storybook configuration files are stored in /storybook.
To use storybook, you can run npm run storybook
. This will start the storybook server and open a new browser window to localhost:6006.
In that new window, you will be able to see the Storybook stories. Storybook does support hot reloading, so any changes to the Vue files should be automatically reflected.
Cypress is used to test our components to ensure changes don't break critical functionality. Cypress runs its tests using the Storybook server, so Storybook must be running on port 6006 for the tests to not timeout.
There are two methods to run Cypress tests.
npm run cypress:open
- Opens the Cypress GUI
npm run cypress:run
- runs the test in the terminal
Cypress tests are located in /cypress/integration
. To view more on Cypress, you can find their docs here
FAQs
A Vue component library for LeadConduit integrations
We found that @activeprospect/integration-components demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 32 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.