Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@silvermine/eslint-config
Advanced tools
JS Code Standards for all SilverMine projects - eslint enforcement
Shareable ESLint configuration for all Silvermine projects.
Because we need it. Whitespace errors are evil. As are the other hundreds of types of errors this protects us from.
It is recommended to run ESLint via a NPM script in package.json
with the command
eslint .
for projects that use this configuration.
Example:
{
"scripts": {
"eslint": "eslint ."
}
}
In addition to the ESLint rules, this package provides configuration for the following:
ln -s ./node_modules/@silvermine/eslint-config/.editorconfig
Provides linting for commit messages of Silvermine projects
Usage: Add a commitlint.config.js
file to the root of the project with the
following and then set up commitlint in the project:
'use strict';
module.exports = {
extends: [ '@silvermine/eslint-config/commitlint' ],
};
See the notes we made in eslint-plugin-silvermine regarding our use of version numbers here. The same decisions made for that repo also apply to this repo, basically for the same reasons.
When choosing which version of this config to use, consider the following:
Updating ESLint in this project requires multiple steps across both this project and @silvermine/eslint-plugin:
git+https
+ git hash URL. The git hash should point
to the commit in @silvermine/eslint-plugin where you updated ESLint.This software is released under the MIT license. See the license file for more details.
FAQs
JS Code Standards for all SilverMine projects - eslint enforcement
We found that @silvermine/eslint-config demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.