
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
ep_author_hover
Advanced tools
Adds author names to span titles (shows on hover), works as authors change their name. Hover includes author color and fast switching between author spans. Hat tip to Martyn York for the initial work on this.
Hover over an author to see their name
Shows the author color on hover Supports fast switching between hovers (Doesn't depend on native browser support)
This plugin adds a new switch called Show Author on Hover to the settings menu. This allows you to disable/enable the display of author names on hover in your browser.
To don't show the author names on hover by default (the user has to activate in manually), add the following to your setting.json:
// disable author hover by default
"ep_author_hover": {
"disabledByDefault": true
}
I don't really like plugins that depdend on manipulating the ACE inner DOM, rewriting this plugin and using events meant I could still have hover functionality without the risk of running into nasty ACE issues down the line. It also meant that as new authors joined and updated their name I could update hte hovers in real time. Previous attempts at writing this plugin have required a browser refresh to know who authors are, that wasn't good enough for me.
FAQs
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.