Product
Socket Now Supports uv.lock Files
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
@dfds-platform/business-components
Advanced tools
Install with npm:
npm install --save @dfds-platform/business-components
Install with yarn:
yarn add @dfds-platform/business-components
For development you need to create a .env
file with they following keys.
key |
---|
AUTH_ISSUER |
AUTH_CLIENT_ID |
CONTENTFUL_SPACE_ID |
CONTENTFUL_TOKEN |
CONTENTFUL_ENVIRONMENT |
Look in .env.development
for default values.
New releases are created in github which will create a new tag.
ADO will pick up on the new tag and publish a version with the that tag using the ci:publish
npm script
yarn link
It can be handy to use developing functionality in the context of an existing app. yarn link
can be used in that case.
A common problem when using yarn link
is that you end of with multiple versions of packages (eg. react). This is
because dependencies are resolved upwards from within the symlinked react-components
folder.
If you are using webpack
you can try setting resolve.symlinks
to false
in your webpack.config.js
to only resolve
dependencies from the apps node_modules
folder.
Gatsby uses webpack under the hood, so in order to set resolve.symlinks
add the following to the gatsby-node.js
file
exports.onCreateWebpackConfig = ({ getConfig, actions, stage }) => {
const config = getConfig()
config.resolve.symlinks = false
actions.replaceWebpackConfig(config)
}
FAQs
Shared react components within DFDS
We found that @dfds-platform/business-components demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.