
Research
Security News
Malicious npm Packages Target BSC and Ethereum to Drain Crypto Wallets
Socket uncovered four malicious npm packages that exfiltrate up to 85% of a victim’s Ethereum or BSC wallet using obfuscated JavaScript.
@chiselstrike/netlify-plugin
Advanced tools
Netlify Build plugin - Integration with ChiselStrike
Supply Chain Security
Vulnerability
Quality
Maintenance
License
Unpopular package
QualityThis package is not very popular.
Found 1 instance in 1 package
High CVE and Socket optimized override available
Sync Netlify and ChiselStrike build from projects in the same Git repository.
Netlify allows you to deploy your frontend and functions as a single unit. With this plugin you can also include your ChiselStrike backend to the bundle. So you can be sure that once your frontend is built, you have a backend ready to persist and serve your data.
It makes the ChiselStrike build a step inside the Netlify build. For that to happen, it assumes that both ChiselStrike and Netlify code are in the same Git repository.
Please install this plugin from the Netlify app. You can find instalation instructions here.
netlify-plugin-chiselstrike
needs a ChiselStrike project ID as configuration
parameter. This parameter can be set through the projectId
input, or through
the CHISELSTRIKE_PROJECT_ID
env var.
You can find your ChiselStrike project ID by opening the Settings tab inside
your projects dashboard in chiselstrike.com
.
FAQs
Netlify Build plugin - Integration with ChiselStrike
The npm package @chiselstrike/netlify-plugin receives a total of 1 weekly downloads. As such, @chiselstrike/netlify-plugin popularity was classified as not popular.
We found that @chiselstrike/netlify-plugin demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket uncovered four malicious npm packages that exfiltrate up to 85% of a victim’s Ethereum or BSC wallet using obfuscated JavaScript.
Security News
TC39 advances 9 JavaScript proposals, including Array.fromAsync, Error.isError, and Explicit Resource Management, which are now headed into the ECMAScript spec.
Security News
Vite releases Rolldown-Vite, a Rust-based bundler preview offering faster builds and lower memory usage as a drop-in replacement for Vite.