Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
accessible-menu
Advanced tools
A JavaScript library to help you generate WAI-ARIA accessible menus in the DOM.
A JavaScript library to help you generate WAI-ARIA accessible menus in the DOM.
This project uses the conventional commit standard, which means your commits should follow a basic template of:
<type>[optional scope]: <description>
[optional body]
[optional footer(s)]
For more detailed information about available types, scopes, breaking changes, etc. please see the official documentation.
This project also provides a command to assist you in formatting commit messages using commitizen:
npm run commit
This project uses Semantic Versioning 2.0.0 to keep track of releases.
Given a version number MAJOR.MINOR.PATCH, increment the:
1. MAJOR version when you make incompatible API changes,
2. MINOR version when you add functionality in a backward compatible manner, and
3. PATCH version when you make backwards compatible bug fixes.
Additional labels for pre-release and build metadata are available as extensions to the MAJOR.MINOR.PATCH format.
For more detailed information about SemVer, please see the official documentation.
When making a release, you should use the provided command:
npm run release
This command uses standard-version to parse through your commits, decide what kind of release will be created, and automatically generates a CHANGELOG.md file for your project. These changes are then commited using the message chore(release): <version number>
.
Once that is done, you can simply run git push --follow-tags origin
to have your release pushed up to the repository.
This project follows a set of coding standards combining StandardJS, Prettier, and JSDoc.
To check your code, you can use ESLint with the provided script:
npm run lint
You can also fix some violations automatically using:
npm run fix
1.0.0-alpha.1 (2019-11-17)
FAQs
A JavaScript library to help you generate WCAG accessible menus in the DOM.
The npm package accessible-menu receives a total of 676 weekly downloads. As such, accessible-menu popularity was classified as not popular.
We found that accessible-menu demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.