
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@humanmade/eslint-config
Advanced tools
Human Made coding standards for JavaScript.
This package is an ESLint shareable configuration, and requires: babel-eslint
, eslint
, eslint-config-react-app
, eslint-plugin-flowtype
, eslint-plugin-import
, eslint-plugin-jsx-a11y
, eslint-plugin-jsdoc
, eslint-plugin-react
, eslint-plugin-react-hooks
, eslint-plugin-sort-destructure-keys
.
To install this config and the peerDependencies when using npm 5+:
npx install-peerdeps --dev @humanmade/eslint-config@latest
(Thanks to Airbnb's package for the command.)
You can then use it directly on the command line:
./node_modules/.bin/eslint -c @humanmade/eslint-config MyFile.js
Alternatively, you can create your own configuration and extend these rules:
extends:
- @humanmade/eslint-config
If you desire to use TypeScript for your project, you will need to add another dependency:
npm install --save-dev @typescript-eslint/parser
Once it's installed, update your configuration with the parser
parameter:
parser: "@typescript-eslint/parser"
extends:
- @humanmade/eslint-config
When installing globally, you need to ensure the peer dependencies are also installed globally.
Run the same command as above, but instead with --global
:
npx install-peerdeps --global @humanmade/eslint-config@latest
This allows you to use eslint -c humanmade MyFile.js
anywhere on your filesystem.
1.1.3 (February 3, 2021)
FAQs
Human Made Coding Standards for JavaScript.
We found that @humanmade/eslint-config demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.