
Research
Malicious NuGet Packages Typosquat Nethereum to Exfiltrate Wallet Keys
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.
@box/item-icon
Advanced tools
<!-- START doctoc generated TOC please keep comment here to allow auto update --> <!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
This library was generated with @box/automation. General overview on how to perform tasks on the generated library can be found in run-tasks Nx documentation.
Your terminal should stay in location of root directory of repository, which is frontend-mono
. That Allows Nx to run action against your project, or multiple project if that is necessary.
Do not navigate to packages/group-shared-features/item-icon
to run commands.
Commands for the project are run using syntax used by Nx:
Syntax: yarn nx <target name> <project name> <option overrides>
| | |
Example: yarn nx test products --watch
All commands used with Nx can be found in project.json
file within your package.
nx storybook item-icon
- launches development environment for UI component.nx build-storybook item-icon
- build static version of storybook with all stories.nx build item-icon
- build package using shared-feature-builder
executor from automation
package.nx build-locales item-icon
- generate i18n/*.js
and i18n/*.properties
files out of i18n/json/*.json
files to be imported by react-intl
.nx lint item-icon
- run linter over package files,nx test item-icon
- runs storybook tests (visual/interactions) and jest unit tests, producing coverage report at the end.nx test-storybook item-icon
- runs storybook tests. You need first to start storybook in separate terminal for this to work.nx test-storybook-local-coverage item-icon
- runs storybook tests, and produces coverage report at the end. Requires running instance of storybook.nx test-storybook-ci item-icon
- build storybook and run storybook tests with coverage output. Designed for CI usage.nx test-jest item-icon
- runs jest unit tests, producing code coverage at the end.nx sonar item-icon
- performs static analysis of code using SonarQube tooling, to detect bugs and code smells. Integrated as one of the steps in CI process.nx chromatic item-icon
- uploads storybook build for review to box chromatic , and performs visual comparison of the UI changes against baseline.nx prepare item-icon
- command run during package publication process orchestrated by Lerna.Code of the feature belongs to webapp-eng. Responsibilities of owning team include control over code quality, providing guidelines for changes, and alignment with other teams regarding changes. It would be a good practice to consult which team, owning or requesting, will be responsible for implementing changes to code.
For translations this package will be leveraging @box/frontend
as it has the required scripts to do translations the Box way, for more information on this checkout their i18n docs [here]
The i18n/
dir is bundled with this package to enable the consuming app to use the translations included in this component it need to adjust it's [TranslationsPlugin],
see EUA's [webpack.base.config.js] and [i18n.config.js] for reference.
FAQs
<!-- START doctoc generated TOC please keep comment here to allow auto update --> <!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
The npm package @box/item-icon receives a total of 1,974 weekly downloads. As such, @box/item-icon popularity was classified as popular.
We found that @box/item-icon demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.
Product
A single platform for static analysis, secrets detection, container scanning, and CVE checks—built on trusted open source tools, ready to run out of the box.
Product
Socket is launching experimental protection for the Hugging Face ecosystem, scanning for malware and malicious payload injections inside model files to prevent silent AI supply chain attacks.