
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@tabula/eslint-config
Advanced tools
This package provides ESLint configurators as shared configs.
We use recommended rules from the following packages:
We add support of React for browser:
Also, we add our opinionated rules configuration on top of it.
Use the package manager pnpm to install @tabula/eslint-config
.
pnpm add @tabula/eslint-config --save-dev
The package provides browser
and node
presets. Add an .eslintrc.json
configuration file to the root of your
project for browser:
{
"extends": "@tabula/eslint-config/browser",
"parserOptions": {
"project": ["tsconfig.json"]
}
}
or for browser tests:
{
"extends": "@tabula/eslint-config/browser-tests",
"parserOptions": {
"project": ["tsconfig.json"]
}
}
or for Node.js:
{
"extends": "@tabula/eslint-config/node",
"parserOptions": {
"project": ["tsconfig.json"]
}
}
Pay attention to the parserOptions.project
option.
We use rules which require type checking. The parser must be configured properly for them.
See more information about parserOptions.project
here.
This project is ISC licensed.
FAQs
Configuration for the ESLint
We found that @tabula/eslint-config demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.