
Research
npm Malware Targets Telegram Bot Developers with Persistent SSH Backdoors
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
eslint-config-mongodb-js
Advanced tools
Shareable configs are designed to work with the extends
feature
of .eslintrc
files. This allows us to easily extend from a base
configuration to provide the right rules for all of the extensive
range of environments we build modules for:
mongodb-js/compass-plugin
mongodb-js/react
mongodb-js/node
mongodb-js/browser
mongodb-js/shell
You can learn more about Shareable Configs on the official ESLint website.
Our eslint-config is based on eslint-config-airbnb.
We make a best effort to explicitly call out any rules we differ from
eslint-config-airbnb will include a JSDoc
comment of @differ #{dang good reason}
.
To use the mongodb-js shareable config, first run:
npm install --save-dev eslint-config-mongodb-js
NOTE You do not need to add multiple
extends: []
in your.eslintrc
! The inheritance of themongodb-js/*
configs inherits bottom up. For example,mongodb-js/compass-plugin
already includesmongodb-js/react
.
compass-plugin
If you're building a MongoDB Compass Plugin, your ./.eslintrc
should be:
{"extends": "mongodb-js/compass-plugin"}
react
For react modules, your ./.eslintrc
should be:
{"extends": "mongodb-js/react"}
node
For vanilla node.js projects, your ./.eslintrc
should be:
{"extends": "mongodb-js/node"}
browser
If you're working on a UI project that uses browserify, your ./.eslintrc
should be:
{"extends": "mongodb-js/browser"}
eslint@5
#49mongodb-js/compass-plugin
config #48Make sure your editor is using the correct version of eslint
. If you're using Visual Studio Code, npm i -g eslint@latest
will resolve this problem.
Apache 2.0
FAQs
eslint sharable configs for mongodb-js.
We found that eslint-config-mongodb-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 38 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
Security News
pip, PDM, pip-audit, and the packaging library are already adding support for Python’s new lock file format.
Product
Socket's Go support is now generally available, bringing automatic scanning and deep code analysis to all users with Go projects.