Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@teamfabric/xpm
Advanced tools
getEnrichedData
function hydrates component's content (component data) by replacing template string with provided data. The output is hydrated/non-hydrated data.
For example, if we have a component with content that says "TODAY ONLY: {%= product.title %} IS 50% OFF!", it returns "TODAY ONLY: HAIRBRUSH IS 50% OFF!" by replacing {%= product.title %}
with HAIRBRUSH
.
getEnrichData
function uses npm package EJS to hydrate template string.
const { getEnrichedData } = require('@teamfabric/xpm')
/**
* Hydrates component data and returns it.
* @param {Object} componentData The component data possibly contains template string.
* @param {Object} data The data to map template string.
* @param {Object} schema The schema validates data type.
* @returns {Object} Hydrated or none-hydrated component data
*/
const data = getEnrichedData({ componentData, data, schema })
FAQs
library used to integrate XPM with client application
The npm package @teamfabric/xpm receives a total of 35 weekly downloads. As such, @teamfabric/xpm popularity was classified as not popular.
We found that @teamfabric/xpm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.