
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@envsa/cspell-config
Advanced tools
CSpell configuration for @envsa/shared-config.
It's a shared CSpell config, plus a command-line tool envsa-cspell
to perform CSpell-related project initialization and linting. Note that automated fixes are handled via an ESLint integration provided in @envsa/eslint-config.
[!IMPORTANT]
You can use this package on its own, but it's recommended to use
@envsa/shared-config
instead for a single-dependency and single-package approach to linting and fixing your project.This package is included as a dependency in
@envsa/shared-config
, which also automatically invokes the command line functionality in this package via itsenvsa
command
To use just this CSpell config in isolation:
Install the .npmrc
in your project root. This is required for correct PNPM behavior:
pnpm dlx @envsa/repo-config init
Add the package:
pnpm add -D @envsa/cspell-config
Add the starter .cspell.json
file to your project root, and add any customizations you'd like:
pnpm exec envsa-cspell init
The CSpell binary should be picked up automatically by VS Code plugins.
You can call it directly, or use the script bundled with the config.
Integrate with your package.json
scripts as you see fit, for example:
{
"scripts": {
"spellcheck": "envsa-cspell lint"
}
}
To create a cspell.config.js
in your project root:
pnpm exec envsa-cspell init
(Note that this will delete the cspell
property in your package.json
!)
Or
To create a cspell
property in package.json
:
pnpm exec envsa-cspell init --location package
(Note that this will delete the cspell.config.js
file in your project root!)
In additional to CSpell's default dictionary configuration, this shared configuration enables a number of dictionaries that ship with CSpell for all file types:
It also includes a number of custom dictionaries distributed with this package, all of which are enabled by default:
envsa-acronyms
Contains acronymsenvsa-files
Contains file extensions and typesenvsa-misc
Contains words that are not acronyms or file extensions/typesIn your project's root cspell.config.js
, you can disable any combination of these dictionaries by adding them to the dictionaries
array with a !
prefix.
For example, do disable the envsa-acronyms
and envsa-misc
dictionaries:
import { cspellConfig } from '@envsa/cspell-config';
export default cspellConfig({
dictionaries: [
'!envsa-acronyms',
'!envsa-misc',
// ...Additional !-prefixed dicitonary names
],
});
In your project's root cspell.config.js
:
import { cspellConfig } from '@envsa/cspell-config';
export default cspellConfig({
words: [
'mountweazel',
'steinlaus',
'jungftak',
'esquivalience',
// ...Additional words
],
});
envsa-cspell
Envsa's CSpell shared configuration tools. (Automated fixes are handled by ESLint.)
This section lists top-level commands for envsa-cspell
.
Usage:
envsa-cspell <command>
Command | Argument | Description |
---|---|---|
init | Initialize by copying starter config files to your project root or to your package.json file. | |
lint | [files..] | Check for spelling mistakes. Matches files below the current working directory by default. |
print-config | Print the resolved CSpell configuration. Package-scoped. Searches up to the root of a monorepo if necessary. |
Option | Description | Type |
---|---|---|
--help -h | Show help | boolean |
--version -v | Show version number | boolean |
See the sections below for more information on each subcommand.
envsa-cspell init
Initialize by copying starter config files to your project root or to your package.json file.
Usage:
envsa-cspell init
Option | Description | Type | Default |
---|---|---|---|
--location | TK | "file" "package" | "file" |
--help -h | Show help | boolean | |
--version -v | Show version number | boolean |
envsa-cspell lint
Check for spelling mistakes. Matches files below the current working directory by default.
Usage:
envsa-cspell lint [files..]
Positional Argument | Description | Type | Default |
---|---|---|---|
files | Files or glob pattern to lint. | array | "**/*" |
Option | Description | Type |
---|---|---|
--help -h | Show help | boolean |
--version -v | Show version number | boolean |
envsa-cspell print-config
Print the resolved CSpell configuration. Package-scoped. Searches up to the root of a monorepo if necessary.
Usage:
envsa-cspell print-config
Option | Description | Type |
---|---|---|
--help -h | Show help | boolean |
--version -v | Show version number | boolean |
This config includes a bunch of words I've happened to have needed to use. Your preferences will vary.
CSpell is configured to automatically ignore files and paths in .gitignore
(via "useGitignore": true
), and to ignore words inside of ```
code fences in markdown and mdx files.
As part of the lint
command process, @envsa/cspell-config
also runs a check to identify any words in your config file's "words"
array that do not actually appear anywhere else in your project. This was inspired by Zamiell's cspell-check-unused-words project.
Eric Mika is the author of the original @kitschpatrol/shared-config project on which this is based.
MIT © Liam Rella
FAQs
CSpell configuration for @envsa/shared-config.
We found that @envsa/cspell-config demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.