
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
@mtburdon/react-components
Advanced tools
A set of reusable React components that can be used across different side projects. Components come with CSS variables for easy customisation.
A set of reusable React components that can be used across different side projects. Components come with CSS variables for easy customisation.
npm run build
- Build the project.
npm run build-watch
- Build the project, watch for changes and rebuild.
npm run start-playground
- Move to the /playground
directory and start the dev server.
npm run i-all
- Install dependences in the root and /playground
folder.
npm run dev
- Build the component library, watch for changes and start the playground, all in parallel. Uses npm-run-all
to run multiple processes at once.
The @mtburdon/react-components
NPM package is set up as a user-scoped package which means the package is scoped to my NPM username - @mtburdon. This is handy as it means the package name is not restricted to package names that haven't yet been taken.
By default, scoped packages are published with private visibility and so to publish the package publicly, the following command is used:
npm publish --access public
Source - Publishing scoped public packages
Used the following articles for initial repo setup:
FAQs
A set of reusable React components that can be used across different side projects. Components come with CSS variables for easy customisation.
The npm package @mtburdon/react-components receives a total of 0 weekly downloads. As such, @mtburdon/react-components popularity was classified as not popular.
We found that @mtburdon/react-components demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.