Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@snowplow/react-native-tracker
Advanced tools
A library for tracking Snowplow events in React Native
Snowplow is a scalable open-source platform for rich, high quality, low-latency data collection. It is designed to collect high quality, complete behavioral data for enterprise business.
To find out more, please check out the Snowplow website and our documentation.
The Snowplow React Native Tracker allows you to add analytics to your React Native apps when using a Snowplow pipeline.
With this library you can collect granular event-level data as your users interact with your React Native applications. It is build on top of Snowplow's Mobile Native iOS and Android Trackers, in order to support the full range of out-of-the-box Snowplow events and tracking capabilities.
From the root of your React Native project:
npm install --save @snowplow/react-native-tracker
npx pod-install
In your ios/Podfile
file (unless using Expo Go), please add the FMDB
dependency with modular_headers
set to true
. This is necessary to make the FMDB
package generate module maps so that it can be used by the tracker:
pod 'FMDB', :modular_headers => true
Then, instrument the tracker in your app and start tracking events. For example:
import { createTracker } from '@snowplow/react-native-tracker';
const tracker = createTracker(
'my-namespace',
{ endpoint: 'https://my-collector.endpoint' }
);
tracker.trackScreenViewEvent({ name: 'myScreenName' });
The Snowplow React Native Tracker also provides first-class support for TypeScript, as it is fully typed.
See also our DemoApp for an example implementation.
Technical Docs | Setup Guide |
---|---|
Technical Docs | Setup Guide |
Assuming a react-native environment is set up, from the root of the repository:
yarn
To run the unit tests, simply execute:
yarn test
Replace "placeholder" with the URI for your Snowplow Mini or other Snowplow collector in DemoApp/App.js
.
For Android:
yarn example android
Note: Linux users who want to run the DemoApp for Android, would also need to run yarn start
in a separate terminal.
For iOS:
yarn example ios
Snowplow React-Native Tracker is being end-to-end tested using Snowplow Micro and Detox. To run these tests locally:
placeholder
value for the collectorEndpoint
variable in example/src/App.js
(use the network IP address of your computer or ngrok).yarn e2e:android
yarn e2e:ios
Feedback and contributions are welcome - if you have identified a bug, please log an issue on this repo. For all other feedback, discussion or questions please open a thread on our discourse forum.
Contributing |
---|
Contributing |
The Snowplow React Native Tracker is copyright 2020-present Snowplow Analytics Ltd, 2019 DataCamp.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this software except in compliance with the License.
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
FAQs
A library for tracking Snowplow events in React Native
The npm package @snowplow/react-native-tracker receives a total of 7,807 weekly downloads. As such, @snowplow/react-native-tracker popularity was classified as popular.
We found that @snowplow/react-native-tracker demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.