
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@unic/estatico-json-schema
Advanced tools
Uses [`Ajv`](https://www.npmjs.com/package/ajv) to validate input files against a [`JSON schema`](http://json-schema.org).
Uses Ajv
to validate input files against a JSON schema
.
$ npm install --save-dev @unic/estatico-json-schema
Specify gulp task:
const gulp = require('gulp');
const env = require('minimist')(process.argv.slice(2));
/**
* Lint data file structure
* Uses Ajv to to validate against a JSON schema
*
* Using `--watch` (or manually setting `env` to `{ watch: true }`) starts file watcher
* When combined with `--skipBuild`, the task will not run immediately but only after changes
*/
gulp.task('data:lint', () => {
const task = require('../estatico-json-schema');
const estaticoWatch = require('@unic/estatico-watch');
const instance = task({
src: [
'./src/**/*.data.js',
],
srcBase: './src',
watch: {
src: [
'./src/**/*.data.js',
'./src/**/*.schema.json',
],
name: 'data:lint',
dependencyGraph: {
srcBase: './',
resolver: {
js: {
match: /(?:require\('(.*?\.data\.js)'\)|require\('(.*?\.schema\.json))/g,
resolve: (match, filePath) => {
if (!(match[1] || match[2])) {
return null;
}
return path.resolve(path.dirname(filePath), match[1] || match[2]);
},
},
json: {},
},
},
watcher: estaticoWatch,
},
}, env);
// Don't immediately run task when skipping build
if (env.watch && env.skipBuild) {
return instance;
}
return instance();
});
Run task (assuming the project's package.json
specifies "scripts": { "gulp": "gulp" }
):
$ npm run gulp data:lint
See possible flags specified above.
plugin(options, env)
=> taskFn
Type: Array
or String
Default: null
Passed to gulp.src
.
Type: String
Default: null
Passed as base
option to gulp.src
.
Type: Object
Default: null
Passed to file watcher when --watch
is used.
Type: Object
Type: Object
Default:
{
// Which part of the input data to validate against the schema
// Both default data and variants will be validated
getData: (content /* , filePath */) => {
const defaultData = content.props;
const variants = content.variants ? Object.values(content.variants).map(v => v.props) : [];
return [defaultData].concat(variants);
},
// Where to find the schema
// eslint-disable-next-line arrow-body-style
getSchemaPath: (content /* , filePath */) => {
return content.meta ? content.meta.schema : null;
},
}
The result of setup.getSchemaPath
is passed to json-schema-ref-parser
.
Type: Object
Default:
{
allErrors: true,
}
Passed to Ajv
.
Type: { info: Function, debug: Function, error: Function }
Default: Instance of estatico-utils
's Logger
utility.
Set of logger utility functions used within the task.
Type: Object
Default: {}
Result from parsing CLI arguments via minimist
, e.g. { dev: true, watch: true }
. Some defaults are affected by this, see above.
Apache 2.0.
FAQs
Uses [`Ajv`](https://www.npmjs.com/package/ajv) to validate input files against a [`JSON schema`](http://json-schema.org).
We found that @unic/estatico-json-schema demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.