
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
@xmtp/react-sdk
Advanced tools
This package provides the XMTP client SDK for React.
To keep up with the latest SDK developments, see the Issues tab in this repo.
To learn more about XMTP and get answers to frequently asked questions, see the XMTP documentation.
These hooks are mostly bindings to the xmtp-js
SDK that expose the underlying data in a React way.
# npm
npm install @xmtp/react-sdk
# pnpm
pnpm install @xmtp/react-sdk
# yarn
yarn add @xmtp/react-sdk
The Node Buffer API must be polyfilled in some cases. To do so, add the buffer
dependency to your project and then polyfill it in your entry file.
Example
import { Buffer } from "buffer";
window.Buffer = window.Buffer ?? Buffer;
If you see a lot of warnings related to source maps, see this issue to learn more.
Access the XMTP React SDK reference documentation.
This client SDK uses a local-first architecture to help you build a production-grade and performant app. To learn more about how we use a local-first architecture, see our official documentation.
Check out our official documentation to get started developing with XMTP and React.
XMTP provides production
, dev
, and local
network environments to support the development phases of your project. To learn more about these environments, see our official documentation.
Important
When you create a client, it connects to the XMTPdev
environment by default. To learn how to use theenv
parameter to set your client's network environment, see Configure the client.
Because this SDK is in active development, you should expect breaking revisions that might require you to adopt the latest SDK release to enable your app to continue working as expected.
XMTP communicates about breaking revisions in the XMTP Discord community, providing as much advance notice as possible. Additionally, breaking revisions in a release are described on the Releases page.
Older versions of the SDK will eventually be deprecated, which means:
The following table provides the deprecation schedule.
Announced | Effective | Minimum Version | Rationale |
---|---|---|---|
There are no deprecations scheduled for this SDK at this time. |
Bug reports, feature requests, and PRs are welcome in accordance with these contribution guidelines.
Run yarn dev
to build the SDK and watch for changes, which will trigger a rebuild.
yarn build
: Builds the SDKyarn clean
: Removes node_modules
, lib
, and .turbo
foldersyarn dev
: Builds the SDK and watches for changes, which will trigger a rebuildyarn format
: Runs prettier format and write changesyarn format:check
: Runs prettier format checkyarn lint
: Runs ESLintyarn test
: Runs all unit testsyarn typecheck
: Runs tsc
FAQs
XMTP client SDK for React apps written in TypeScript
We found that @xmtp/react-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.