
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
eslint-config-altheajs
Advanced tools
Althea Web Service's eslint
configuration.
You can view this package on NPM: click here
This package supports the following by default out of the box:
eslint-config-airbnb
- React with hooks supporteslint-config-prettier
- Prettier support. Prettier configs will override the ESLint rules associated with style choices. In other words, Pretter > ESLint
.eslint-plugin-vue
- Vue supportThis package also has the option for supporting TypeScript projects as well:
eslint-config-airbnb-typescript
- React with hooks supportnpm install --save-dev eslint-config-altheajs
yarn add --dev eslint-config-altheajs
The simplest way to install and use the default config is to reference it directly in your package.json
file as follows:
{
// ...package.json
"eslintConfig": {
"extends" : ["altheajs"]
}
}
If you'd like to extend the configurations, create a .eslintrc.js
file at the root of your project that contains the following:
module.exports = {
"extends": ["altheajs"], // you can omit "eslint-config-"
// if using typescript
"parserOptions": { "project": "./tsconfig.json" }
// ...more custom config overrides
};
If you're using a typescript project, you can use the exported TypeScript ESLint configuration.
{
// ...package.json
"eslintConfig": {
"extends": ["altheajs/typescript"]
}
}
Since this package already bundles the eslint-config-prettier
package under the hood, there is no need to install the dependency yourself. You can use your Prettier config as you would normally in your project, and ESLint will prefer Prettier for style changes over its own.
You can add in an npm script to your package.json
which will apply lint rules across all the file patterns specified. Simply add the following to apply to all files:
{
// ...package.json
"scripts": {
// check for linting errors
"lint:quality": "npx eslint -c .eslintrc.js . --ext .js,.jsx,.ts,.tsx"
// fix and apply the rules to those that can be fixed
"fix:quality": "npx eslint -c .eslintrc.js . --ext .js,.jsx,.ts,.tsx --fix",
}
}
Install ESLint extension: View → Extensions
then find and install the ESLint extension.
Reload the editor.
In your user settings Code -> Preferences -> Settings
add the following settings:
{
// ...settings.json
"editor.codeActionsOnSave": {
"source.fixAll.eslint": true
}
}
Check out all of ESlint's configuration options.
FAQs
An eslint config, what else?
We found that eslint-config-altheajs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.