
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@config-plugins/react-native-siri-shortcut
Advanced tools
Config plugin for react-native-siri-shortcut package
Expo Config Plugin to auto-configure react-native-siri-shortcut when the native code is generated (npx expo prebuild).
Ensure you use versions that work together!
expo | react-native-siri-shortcut | @config-plugins/react-native-siri-shortcut |
|---|---|---|
| 54.0.0 | 3.2.4 | 11.0.0 |
| 53.0.0 | 3.2.4 | 10.0.0 |
| 52.0.0 | 3.2.4 | 8.0.0 |
| 51.0.0 | 3.2.4 | 7.0.0 |
| 50.0.0 | 3.2.4 | 6.0.0 |
| 49.0.0 | 3.2.3 | 5.0.0 |
| 48.0.0 | 3.2.2 | 4.0.0 |
This package cannot be used in the "Expo Go" app because it requires custom native code.
First install the package with yarn, npm, or npx expo install.
npx expo install react-native-siri-shortcut @config-plugins/react-native-siri-shortcut
After installing this npm package, add the config plugin to the plugins array of your app.json or app.config.js:
{
"plugins": ["@config-plugins/react-native-siri-shortcut"]
}
Next, rebuild your app as described in the "Adding custom native code" guide.
When working with Siri Shortcuts, you need to define their identifiers on the Xcode project. To achieve the same result using this plugin, just pass an array of strings with the identifiers of your shortcuts, and they will be added automatically during the build cycle:
{
"plugins": [
[
"@config-plugins/react-native-siri-shortcut",
["com.example.InitiateWorkout", "com.example.FinishWorkout"]
]
]
}
FAQs
Config plugin for react-native-siri-shortcut package
The npm package @config-plugins/react-native-siri-shortcut receives a total of 308 weekly downloads. As such, @config-plugins/react-native-siri-shortcut popularity was classified as not popular.
We found that @config-plugins/react-native-siri-shortcut demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 10 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.