
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@livechat/design-system-metrics
Advanced tools
The metrics package provides a way to gather and display data in a consistent manner. It is designed to be customizable and easy to incorporate into your projects. Right now, there are two types of metrics available:
DesignTokens usage
- a metric that shows how many times a design token is used in the project versus how many times inline color values are used.Component usage
- a metric that shows how many times a component is used in the project.Run the following command using npm (or with you other favorite package manager, eg. yarn):
npm install -D @livechat/design-system-metrics
Library exports two functions that you can use to collect metrics data.
generateAndSendMetrics
- a function that scans the project and sends the metrics data to the Flagman Service for further processing.generateMetrics
- a function that scans the project and returns an object with metrics data. Can be used to locally gather metrics data.These functions are designed to be used in conjunction with the Flagman Service, which is a part of the LiveChat infrastructure.
generateAndSendMetrics
A main function that scans the project and sends the metrics data to the Flagman Service for further processing. It takes a few configuration objects as arguments:
scannerConfig
- a configuration object for the react-scanner package. The only required property is rootDir
- a path to the root directory of the project.flagmanConfig
- a configuration object for the Flagman Service. It should contain the following properties:
protocol
- a protocol that is used to authenticate the request.host
- a host of the Flagman Service.port
- a port of the Flagman Service.apiKey
- an API key that is used to authenticate the request.APP_ID
- an ID of the application that the metrics are gathered for. Available AppIDs are: AGENT_APP
, ACCOUNTS
, HELPDESK
.BUILD_ID
- an ID of the build that the metrics are gathered for.Best way to automate metrics collection is to create a script in your project and run it as a part of your CI/CD pipeline. For example, you can add a metrics
script to your package.json
file and run it using npm run metrics
command.
{
"scripts": {
"metrics": "node ./scripts/metrics.js"
}
}
// scripts/metrics.js
const { generateAndSendMetrics } = require('@livechat/design-system-metrics');
(async () => {
const APP_ID = 'AGENT_APP' | 'ACCOUNTS' | 'HELPDESK';
await generateAndSendMetrics(
{ rootDir: 'src' },
{ protocol: 'http', host: 'flagman_host', port: 'flagman_port', apiKey: 'api_key' },
APP_ID,
BUILD_ID
);
})();
generateMetrics
A simplified function that only scans the project and returns an object with metrics data. It takes a configuration object as an argument. The configuration object should contain the following properties:
rootDir
- a path to the root directory of the project.reactScannerConfig
(optional) - a configuration object for the react-scanner package.newDSLibraryAlias
(optional) - an alias for the new design system library. By default, it is set to @livechat/design-system-react-components
.oldDSLibraryAlias
(optional) - an alias for the old design system library. By default, it is set to @livechat/design-system
.Example usage:
const { generateMetrics } = require('@livechat/design-system-metrics');
const metricsData = await generateMetrics({
rootDir: '/path/to/your/project',
});
Example result:
{
"newDS": {
"components": [{
"name": "Button",
"instances": 124,
"props": {"onClick": 115, "kind": 124, "children": 124}
}],
"totalUses": 2097
},
"legacyDS": {
"components": [],
"totalUses": 488
},
"designTokenUsage": { "designTokenCount": 999, "colorStringLiteralCount": 999 }
}
FAQs
LiveChat Design System Metrics
We found that @livechat/design-system-metrics demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 67 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.