
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@colony/colony-example-react
Advanced tools
An example project using colonyJS using React!
This is a built out version of the colony-starter-react package with more examples.
>=10.13.0
>=1.12.0
>=18.09.0
You may find it helpful to use Node Version Manager (nvm
) to manage Node versions.
If you are using Linux, check out Linux Setup to ensure Yarn and Docker are set up accordingly.
Globally install the colony-cli package:
yarn global add @colony/colony-cli
Move to your working directory and unpack the colony-example-react package:
colony build colony-example-react
Move to your new project directory and follow the instructions below:
cd colony-example-react
Alternatively, you can use npx and unpack the colony-example-react package without installing the colony-cli package.
npx -p @colony/colony-cli colony build colony-example-react
Open a new terminal window and start Ganache:
yarn start-ganache
Open a new terminal window and deploy the colonyNetwork contracts:
yarn deploy-contracts
Once the contracts have been deployed, start TrufflePig:
yarn start-trufflepig
Open a new terminal window and run the seed network script:
yarn seed-network
Once the network has been seeded, start the development server:
yarn start
Open your browser and check out the example:
Open a new terminal window and run the example tests:
yarn test
If you do not want to use the default version of the colonyNetwork smart contracts defined by the colony-cli package, you can update the "deploy-contracts"
scripts property in your package.json
file to use a specific version. This can be a branch name, a commit hash, or a version tag.
"deploy-contracts": "colony service deploy-contracts --specific glider",
FAQs
A simple example project built with Colony
We found that @colony/colony-example-react demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.