
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
ember-cli-tree-shake
Advanced tools
This Ember CLI addon uses tree shaking to discover dead code within an Ember application.
Currently, only dead/unused computed properties are considered, with a few caveats:
npm install --save-dev ember-cli-tree-shake
ember tree-shake
This addon will currently look for computed properties and observers that are not actually used in either internal methods or in the associated template. For example:
Ember.Component.extend({
foo: true,
used: Ember.computed.alias('foo'),
unused: Ember.computed.not('used')
});
ember-cli-tree-shake
will identity that the unused
property isn't actually
used within the component.
However, if there was an associated template:
{{#if (or used unused)}}
Hello, world!
{{/if}}
In this case, the "unused
" property is actually being evaluated in the
template, and therefor isn't actually dead code. ember-cli-tree-shake
would
no longer identify it as such.
Finally, ember-cli-tree-shake
will do a 2nd, 3rd ... nth pass over the tree
and keep shaking until no more dead code falls off.
npm test
FAQs
Use tree shaking to discover dead code in your Ember app
The npm package ember-cli-tree-shake receives a total of 1 weekly downloads. As such, ember-cli-tree-shake popularity was classified as not popular.
We found that ember-cli-tree-shake demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.