Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@shopify/app-bridge
Advanced tools
[![Build Status](https://travis-ci.com/Shopify/app-bridge.svg?token=RBRyvqQyN525bnfz7J8p&branch=master)](https://travis-ci.com/Shopify/app-bridge) [![codecov](https://codecov.io/gh/Shopify/app-bridge/branch/master/graph/badge.svg?token=nZ21m39Dr6)](https:
@shopify/app-bridge
The App Bridge is a library that enables Apps on Shopify to access native Shopify features across different platforms.
yarn add @shopify/app-bridge
Import the library from the @shopify/app-bridge
package and provide
a configuration:
import createApp, {getShopOrigin} from '@shopify/app-bridge';
const app = createApp({
apiKey: 'API key from Shopify Partner Dashboard',
shopOrigin: getShopOrigin(),
});
A list of available actions can be found in the actions source folder.
yarn start
Start a development serveryarn build
Build the library, compiling the source TypeScript into JavaScriptyarn clean
Remove any artefacts produced by the build
scriptyarn lint
Run the source linteryarn check
Run the TypeScript type checkeryarn test
Run the testsyarn test:watch
Run the tests in watch mode and auto-rerun on changesyarn test:coverage
Run the tests and generate a coverage reportTo enable automatic prettier formatting copy or link the pre-commit script to
.git/hooks/pre-commit
and make sure it's executable.
FAQs
**[Join our team and work on libraries like this one.](https://www.shopify.ca/careers)**
The npm package @shopify/app-bridge receives a total of 63,419 weekly downloads. As such, @shopify/app-bridge popularity was classified as popular.
We found that @shopify/app-bridge demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 25 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.