
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
@metarouter/analytics.js-integrations
Advanced tools
This repo stores the majority of the analytics.js integrations that Segment currently supports. It is organized as a monorepo with each individual integration packaged and deployed as their own npm modules.
To start contributing, please ensure you have the following installed on your local machine:
Once these pre-requisites are met, feel free to clone the repo locally and install the required dependencies:
git clone https://github.com/segmentio/analytics.js-integrations && cd analytics.js-integrations
yarn
All individual integrations are stored in the integrations/ directory. We recommend navigating into the individual integration you are contributing to in your terminal rather than working from the root directory:
cd integrations/<INTEGRATION_NAME>
Please note, there is currently no way for user's of these integrations to choose specific versions. Therefore, all changes must always be fully backwards compatible. If a change is breaking it will not be considered.
If you need to add an external dependency to an integration, please ensure you add it within the integration directory, not the root directory. That being said, please keep in mind that these integrations are run client side. Please only add external dependencies if it is critical to your code changes.
Each integration directory has an npm script called test that you can use to easily run the unit tests with via yarn test.
You can test changes to integrations locally with the a.js compiler.
This project uses eslint to ensure uniform code formatting standards are maintained. You can see the specific eslint config in the root .eslintrc file. A pre-commit hook is used to help automate this process for you.
Please make sure your PR includes the new version in package.json as well as an update to the integration's HISTORY.md file describing the change.
All releases are handled by Segment engineers. Releases will be managed after a change has been approved and merged.
FAQs
Metarouter analytics.js-integrations
We found that @metarouter/analytics.js-integrations demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.