
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@glossier/eslint-config
Advanced tools
We are following JavaScript Standard Style, with some additional guidelines. We are also extending the react, jest, and jsx-a11y ESLint plugins with the recommended configuration.
yarn add --dev eslint@^4.19.1 @glossier/eslint-config
To get started, extend Glossier's configuration in your .eslintrc
.
{
"extends": "@glossier"
}
That's it -- you can now lint your code.
./node_modules/.bin/eslint .
As mentioned above, we are following JavaScript Standard Style, with the following extra rules:
We define a maximum line length of 100
characters.
// bad
const books = ['JavaScript: The Good Parts', 'Eloquent JavaScript A Modrn Introduction to Programming']
// good
const books = [
'JavaScript: The Good Parts',
'Eloquent JavaScript A Modrn Introduction to Programming'
]
Prefer using const
over let
or var
.
// bad
let a = 1
// good
const a = 1
Prefer using let
over var
.
// bad
var foo = 'bar'
foo = 'baz'
// good
let foo = 'bar'
foo = 'baz'
Copyright 2018 Glossier Inc.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
FAQs
How we write JavaScript at Glossier
The npm package @glossier/eslint-config receives a total of 1 weekly downloads. As such, @glossier/eslint-config popularity was classified as not popular.
We found that @glossier/eslint-config demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 13 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.