
Product
Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.
@nebula.js/sn-nav-menu
Advanced tools
A navigation menu object for Qlik Sense implemented as a nebula.js supernova.
pnpm installpnpm build (or pnpm build:watch)pnpm startRun unit tests with:
pnpm test:unit
Rendering tests are running playwright. Execute rendering tests with pnpm test:e2 --headed.
Rendering test compares a baseline snapshot with a current version of the same object. The output is then stored under baselines. It is important to take the baseline from the build in your PR and not your local baselines which is stored under baselines-local. The report with baselines can be found under summary under a link called test report.
You can use the action called update snapshot to trigger a commit into your branch that automatically updates the snapshots.
Run lint with:
pnpm lint
Trigger the github action Build, validate, (release) and make sure you tick the release checkbox.
FAQs
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.

Research
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infostealer during installation.

Research
/Security News
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.