Security News
The Risks of Misguided Research in Supply Chain Security
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
derby-debug
Advanced tools
Derby app plugin to add debugging utility functions.
app.use(require('derby-debug'));
When included, this plugin will set window.APP
and window.MODEL
in the browser when the application is ready. These make debugging from the console much easier.
app.findComponent(name, [index])
Returns a component with a given view name. This is the same name that is shown in the comment representing the component instance when you inspect the DOM with the console's Elements Panel. An index
may be optionally passed to return the nth component on the page.
app.componentCommand(comment)
Returns a command that can be entered into the console to find the same component again. This is handy for the following workflow:
copy(APP.componentCommand($0))
copy()
and $0
are features of the Chrome console. Naturally, copy()
copies a value to the clipboard, and $0
returns the node that is currently selected in the Elements panel.
model.logEvents([subpath])
This method adds an event listener that console.logs out the arguments of any model event. A subpath argument is optional.
For example, try:
MODEL.logEvents();
MODEL.logEvents('_page');
app.findComponent('my-component:index').model.logEvents();
FAQs
Derby app plugin to add debugging utility functions
The npm package derby-debug receives a total of 1 weekly downloads. As such, derby-debug popularity was classified as not popular.
We found that derby-debug demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.