
Product
Announcing Socket Certified Patches: One-Click Fixes for Vulnerable Dependencies
A safer, faster way to eliminate vulnerabilities without updating dependencies
@vevo/babel-config-vevo
Advanced tools
babel requires a couple of core libraries to be installed seperately in each project's directory, so you'll have to run a little script to install the correct versions of the packages required.
# Installation and Update script for peer deps
(
export PKG=@vevo/babel-config-vevo;
yarn add --dev $PKG@latest;
npm info "$PKG@latest" peerDependencies --json | command sed 's/[\{\},]//g ; s/: /@/g' | xargs yarn add --dev "$PKG@latest"
)
make a config file: .babelrc:
If you're building from the command line, you might also need to run yarn add @babel/cli
{
"presets": [
"module:@vevo/babel-config-vevo",
[
"@babel/preset-env",
{
targets: "> 5%"
}
],
]
}
{
"presets": [
"module:@vevo/babel-config-vevo",
[
"@babel/preset-env",
{
targets: {
"node": true
}
}
],
]
}
First change the package.json peer dependency versions to whatever the newest versions of babel are.
You may also be able to delete some plugins if they have transitioned into stage 4.
Then you will need to rerun the script mentioned above in each repo that needs the update.
Mesa handles all of the preset-env configuration. So you will need to update the peer deps and this package in mesa directly. Each individual mesa app then just needs to update mesa.
FAQs
Default babel config for js projects
We found that @vevo/babel-config-vevo demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 13 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
A safer, faster way to eliminate vulnerabilities without updating dependencies

Product
Reachability analysis for Ruby is now in beta, helping teams identify which vulnerabilities are truly exploitable in their applications.

Research
/Security News
Malicious npm packages use Adspect cloaking and fake CAPTCHAs to fingerprint visitors and redirect victims to crypto-themed scam sites.