
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
@sonder/eslint-config
Advanced tools
Provide Sonder's .eslintrc as an extensible shared config
Install package and it's peer dependencies
yarn add @sonder/eslint-config babel-eslint eslint eslint-plugin-babel eslint-plugin-import eslint-plugin-react --dev
Inside a .eslintrc file in your repository's root folder, add this config:
{
"extends": "@sonder",
"rules": {
// Repo-specific rules to override this config
}
}
To prove/validate that a rule is validating what it is supposed to, add a test each time a rule is added or modified in this repo, not the extended rule sets.
test/error/ do not follow eslint rules and should throw eslint errors.test/pass/ follow eslint rules and should throw no error.Add all validFiles and errorFiles to test/test.js and run:
yarn test
All checks passed!
git clone git@github.com:Flatbook/eslint-config-sonder.gitindex.jsgit commit -m "Add rule XYZ"yarn publish --new-version minorFAQs
Provide Sonder's .eslintrc as an extensible shared config
We found that @sonder/eslint-config demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.