
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@layer0/devtools
Advanced tools
In-browser devtools for the Layer0
You need both @layer0/devtools and @layer0/prefetch installed in your project
npm install --save @layer0/devtools @layer0/prefetch
You need to enable @layer0/prefetch in your service worker.
Check our prefetching guide, or @layer0/prefetch README for more information
Note: you can skip this step if you are using @layer0/next or @layer0/nuxt
Then load the widget in the Browser's javascript
import installDevtools from '@layer0/devtools/install'
installDevtools()
Alternatively you can also inject the widget install script directly in your HTML <head>
<script defer src="/__layer0__/devtools/install.js"></script>
By default, the devtools is enabled when your app is served from localhost, 127.0.0.1 or any *.layer0-limelight.link domain.
But that can be customized:
In Layer0 console environment, set the PREVIEW_LAYER0_DEVTOOLS_ENABLED to true or false to explicitly enable or disable the devtools on the given environment, no matter what domain it runs on.
Point your browser to /__layer0__/devtools/enable or /__layer0__/devtools/disable to explicitly enable/disable the devtools on your browser. This takes precedence over the environment config and the domain default.
If the devtools was previously enabled and you disable it, you may want to remove the service worker to get rid of the devtools-specific route handlers that were installed on-demand when enabling it. This can be done using the Application tab in Chrome Developer Tools.
FAQs
In-browser devtools for the [Layer0](https://layer0.co/)
The npm package @layer0/devtools receives a total of 55 weekly downloads. As such, @layer0/devtools popularity was classified as not popular.
We found that @layer0/devtools demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.