Security News
The Risks of Misguided Research in Supply Chain Security
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
@brisk-docs/gatsby-generator
Advanced tools
Brisk Docs is a package oriented documentation system that lets you write useful, interactive docs alongside your code. It is aimed at documenting packages in a mono-repo
Start by installing Brisk Docs in your project
npm install @brisk-docs/website
To start your docs website locally:
npm run brisk dev
To produce a static build of the website that can be statically hosted:
npm run brisk build && npm run brisk export
Brisk Docs by default uses file and folder name conventions to find docs in your codebase and display them in a organised way.
For guides and docs relating to your project or repository as a whole, Brisk Docs will display any Markdown or MDX files placed in the /docs
folder at the top of your repository. This is a good place to put user guides, tutorials, contributor guidelines etc.
Brisk Docs has first class support for multi-package repos. All packages found in the /packages
directory of your project will have documentation generated automatically.
Read more about package documentation in our package documentation guide.
MDX means that we parse markdown a little differently, and treat jsx blocks as react components.
This means that you can write:
# Just a regular markdown package
import MyComponent from './src/myComponent'
<MyComponent>I could not be expressed just with markdown<.MyComponent>
Just some more _regular_ markdown here.
In addition to being able to render any markdown, brisk provides two components that can be used on any page without being imported.
They are <Props />
and <FileViewer />
- these are exports of pretty-proptypes and file-viewer
FAQs
The Brisk website documenter
We found that @brisk-docs/gatsby-generator demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.