
Research
/Security News
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
@jeremistadler/unused-unloved
Advanced tools
Find all the unused files 🗂 by checking all unused imports in your React project (no need for a webpack plugin). List out all those files in a nice JSON file to do what you like with!
🌳Tree shaking is great but what happens when you have so many 📁files in your dev environment you can't remember which ones are actually in use😵🤷♂️🤷♀️ and those that are currently dormant? Time for some spring cleaning, enter... unused-unloved🎉🎉 !
Once unused-unloved has run it will output an 📄unused-file-report.json
You can now use the contents of this folder to do as you wish, personally, I suggest copy and paste it into http://json2table.com/
npm install -g unused-unloved
Open your React (or similar) project and make sure you are the same level as your /src folder and just run:
unused-unloved
unused-unloved created by Chris Watson - cwatson88⌨
FAQs
Find all the unused files 🗂 by checking all unused imports in your React project (no need for a webpack plugin). List out all those files in a nice JSON file to do what you like with!
We found that @jeremistadler/unused-unloved demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
Security News
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local dev and CI.
Research
The Socket Threat Research Team is tracking weekly intrusions into the npm registry that follow a repeatable adversarial playbook used by North Korean state-sponsored actors.