
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
cra-template-sls
Advanced tools
Run this command to use this template:
npx create-react-app your-project --template sls
This is a Create React App bootstrapped with my preferred setup of ESLint, Prettier, and a bunch of libraries common to most projects, such as lodash, date-fns, core-js, validator, etc.
It comes with cypress.json and jsconfig.json that sets the src folder as the root url for React and Cypress.
After installing this template with CRA, do the following:
Cut and paste the contents of pkg.json
into your package.json. The husky, lint-staged, and jest configurations are not currently supported by templates. Also, the CRA team doesn't like separating dev dependencies, but I do, so you need these, as well. You can delete the pkg.json
file after you're finished.
Run yarn upd
. This will make sure that all of the libraries are updated to the latest versions.
In the project directory, you can run:
yarn start
Runs the app in the development mode.
yarn cypress
Launches the Cypress test runner.
yarn upd
Update all packages to the latest versions and launches the development server.
yarn test
Launches the test runner in the interactive watch mode.
See the section about running tests for more information.
yarn test-cov
Launches the test runner and also generates a code coverage report.
yarn test-cov-view
Requires browser-sync to be install globally. Watches the code coverage folder and automatically refreshes the browser when it changes.
FAQs
SLS Template for Create React App
We found that cra-template-sls demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.