
Security News
PodRocket Podcast: Inside the Recent npm Supply Chain Attacks
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
@fullstackio/newline-mdx-components
Advanced tools
This is a boilerplate project for writing React NPM modules (or component libraries) in TypeScript. The code is compiled and published to NPM via CircleCI v2 Workflows and Github Releases.
This boilderplate includes a Storybook to visualize and demonstrate your components. The Storybook is automatically deployed to Zeit once configured (see the Storybook for this template here). This allows you to test each PR visually and in isolation.
v.*.*.*
pattern)yarn install
yarn start
index.ts
v.*.*.*
version number). CircleCI will automatically build and deploy.yarn
Scriptstest
- run unit teststest:cover
- run unit tests with test coveragelint
- check eslint
and prettier
ruleslint:fix
- autofix unmet eslint
and prettier
ruleslocal-pack
- create the tgz
package locally to test consumers without publishingstart
- start the storybook server and automatically open in browsercompile
- standard typescript compile tsc
now-build
- used by Zeit when building your storybook for deployment (do not rename this script)Before each commit, husky
and lint-staged
will automatically lint your staged ts, tsx, js, jsx
files.
You need to configure one environment variable in CircleCI, for publishing to NPM.
NPM_TOKEN
You need to authorize Zeit with your GitHub account to enable automatic deployments. Once configured, you can enable Zeit to deploy any repository that contains a now.json
file.
I recommend enabling Dependabot on this repository to keep your dependencies up to date. Each dependency update will be created as a PR, which will automatically validate via Circle CI and you can manually validate via Zeit.
This code is released under the MIT license - feel free to use it.
Please contribute any improvements or fixes to this project!
To make sure you have a pleasant experience, please read the code of conduct. It outlines core values and beliefs and will make working together a happier experience.
FAQs
mdx components for newline
We found that @fullstackio/newline-mdx-components demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.