
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@stencil/eslint-plugin
Advanced tools
ESLint rules specific to Stencil JS projects.
Install this plugin in your project via:
npm i --save-dev @stencil/eslint-plugin
The plugin exports 3 flat configs for use with eslint >= 9:
// eslint.config.mjs
import stencil from '@stencil/eslint-plugin';
export default [
...
stencil.configs.flat.recommended,
...
];
Alternatively:
// eslint.config.js
const stencil = require('@stencil/eslint-plugin');
module.exports = [
...
stencil.configs.flat.recommended,
...
];
By default, ESLint will ignore your node_modules/
directory. Consider adding a .eslintignore
file at the root of
your project with any output target directories to avoid false positive errors from ESLint.
# place any directories created by the Stencil compilation process here
dist
loader
www
Lint all your project:
npm run lint
.eslintrc.json
configuration file:
{
"parserOptions": {
"project": "./tsconfig.json"
},
"extends": [
"plugin:stencil/recommended"
]
}
This rule catches Stencil public methods that are not async.
This rule catches Stencil Props with a default value of true
.
This rule catches Stencil Component banned tag name prefix.
This rule catches Stencil Component class name not matching configurable pattern.
This rule catches Stencil decorators in bad locations.
This rule catches Stencil decorators style usage.
This rule catches Stencil Element decorator have the correct type.
This rule catches Stencil method hostData.
This rule catches Stencil Methods marked as private or protected.
This rule catches Stencil Watchs with non existing Props or States.
This rule catches own class methods marked as public.
This rule catches own class properties marked as public.
This rule catches Stencil Listen with vdom events.
This rule catches Stencil Props marked as private or protected.
This rule catches Stencil Props marked as non readonly, excluding mutable ones.
This rule catches Stencil Render returning array instead of Host tag.
This rule catches Stencil Props, Methods and Events to define jsdoc.
This rule catches Stencil Component required tag name prefix.
This rule catches Stencil Prop names that share names of Global HTML Attributes.
This rule catches modules that expose more than just the Stencil Component itself.
This rule catches Stencil Prop marked as mutable but not changing value in code.
{
"stencil/async-methods": "error",
"stencil/ban-prefix": ["error", ["stencil", "stnl", "st"]],
"stencil/decorators-context": "error",
"stencil/decorators-style": [
"error", {
"prop": "inline",
"state": "inline",
"element": "inline",
"event": "inline",
"method": "multiline",
"watch": "multiline",
"listen": "multiline"
}],
"stencil/element-type": "error",
"stencil/host-data-deprecated": "error",
"stencil/methods-must-be-public": "error",
"stencil/no-unused-watch": "error",
"stencil/own-methods-must-be-private": "error",
"stencil/own-props-must-be-private": "error",
"stencil/prefer-vdom-listener": "error",
"stencil/props-must-be-public": "error",
"stencil/props-must-be-readonly": "error",
"stencil/render-returns-host": "error",
"stencil/required-jsdoc": "error",
"stencil/reserved-member-names": "error",
"stencil/single-export": "error",
"stencil/strict-mutable": "error"
}
When submitting new rules please:
All contributions welcome.
FAQs
ESLint rules specific to Stencil JS projects.
The npm package @stencil/eslint-plugin receives a total of 3,956 weekly downloads. As such, @stencil/eslint-plugin popularity was classified as popular.
We found that @stencil/eslint-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.