
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
eslint-config-humanmade
Advanced tools
Human Made coding standards for JavaScript.
This package is an ESLint shareable configuration, and requires babel-eslint
, eslint
, eslint-config-react-app
, eslint-plugin-flowtype
, eslint-plugin-import
, eslint-plugin-jsx-a11y
, eslint-plugin-react
.
To install this config and the peerDependencies when using npm 5+:
npx install-peerdeps --dev eslint-config-humanmade@latest
(Thanks to Airbnb's package for the command.)
You can then use it directly on the command line:
eslint -c humanmade MyFile.js
Alternatively, you can create your own configuration and extend these rules:
extends:
- humanmade
If you desire to use TypeScript for your project, you will need to add another dependency:
npm install --save-dev @typescript-eslint/parser
Once it's installed, update your configuration with the parser
parameter:
parser: "@typescript-eslint/parser"
extends:
- humanmade
When installing globally, you need to ensure the peer dependencies are also installed globally.
Run the same command as above, but instead with --global
:
npx install-peerdeps --global eslint-config-humanmade@latest
This allows you to use eslint -c humanmade MyFile.js
anywhere on your filesystem.
1.0.0 (July 31, 2020)
WordPress-Docs
by default in PHPCS #177$namespace.php
in function files #99FunctionCallSignature
inconsistency in phpcbf #200.editorconfig
for YAML & Markdown files #175package.json
files with tabs #175.editorconfig
to project root #175readme.md
to README.md
#175composer.json
description #175package.json
files meta #175<file>
, <basepath>
and testVersion
from ruleset #187, #198FAQs
Human Made Coding Standards for JavaScript.
The npm package eslint-config-humanmade receives a total of 56 weekly downloads. As such, eslint-config-humanmade popularity was classified as not popular.
We found that eslint-config-humanmade demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.