
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
base-config-schema
Advanced tools
Schema for the base-config plugin, used for normalizing config values before passing them to config.process().
Schema for the base-config plugin, used for normalizing config values before passing them to config.process().
Install with npm:
$ npm install --save base-config-schema
var Base = require('base');
var config = require('base-config');
var configSchema = require('base-config-schema');
var app = new Base();
app.use(config());
var schema = configSchema(app);
var pkg = require('./package');
var obj = schema.normalize(pkg.verb);
app.config.process(obj, function(err) {
if (err) throw err;
});
Register async template helpers. Can be an array of module names or filepaths, or an object where the keys are filepaths or module names, and the values are options objects.
Example
{
"asyncHelpers": ["helper-foo", "helper-bar"]
}
Disable one or more options. This is the API-equivalent of calling app.disable('foo'), or app.option('foo', false).
Example
{disable: 'foo'}
// or
{disable: ['foo', 'bar']}
Enable one or more options. This is the API-equivalent of calling app.enable('foo'), or app.option('foo', false).
Example
{enable: 'foo'}
// or
{enable: ['foo', 'bar']}
config method for mapping declarative configuration values to other 'base… more | homepageoption, enable and disable. See the readme… more | homepagePull requests and stars are always welcome. For bugs and feature requests, please create an issue.
(This document was generated by verb-generate-readme (a verb generator), please don't edit the readme directly. Any changes to the readme must be made in .verb.md.)
To generate the readme and API documentation with verb:
$ npm install -g verb verb-generate-readme && verb
Install dev dependencies:
$ npm install -d && npm test
Jon Schlinkert
Copyright © 2016, Jon Schlinkert. Released under the MIT license.
This file was generated by verb-generate-readme, v0.1.28, on July 30, 2016.
FAQs
Schema for the base-config plugin, used for normalizing config values before passing them to config.process().
We found that base-config-schema demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.