Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
create-react-native-plugin
Advanced tools
Template for creating React Native plugins without native code.
Starting point for creating React Native plugins in TypeScript without native code.
bun create react-native-plugin react-native-my-plugin
bunx create-react-native-plugin@latest react-native-my-plugin
This will bootstrap a new plugin inside a folder named react-native-my-plugin
accordingly. Inside that folder the commands mentioned hereafter are available. The prefix react-native-
is optional and will be removed where the React Native context is implied.
Start working on your plugin by editing index.tsx
which will be the entry point for the plugin.
Since you probably don't want to blind-code the whole plugin use the following command to generate an up-to-date React Native app which includes the plugin:
bun app
This will create an app inside /app
where except /app/App.tsx
all files are gitignored. Here you can try out various use cases of the plugin and use this as a way to demonstrate the plugin. The app can be started as usual by running bun ios
or bun android
inside the /app
folder.
bun copy
Running the above in the root folder will watch the plugin source code for any kind of changes and copy over the changes to the app which will then automatically hot-reload.
Don't forget to always check your plugin both on Android and iOS even though your not using native code the provided components might still differ depending on the platform.
The template is configured to work with Jest out of the box. All non-native functionality can be tested from the terminal. With the following command you can run the tests which are found in a folder with the same name:
bun run test
If you have issues building the app for iOS try the following
sudo gem install cocoapods
app/ios
folder with pod update
The following plugins have been created with create-react-native-plugin as a starting point.
FAQs
Template for creating React Native plugins without native code.
We found that create-react-native-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.