
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
eslint-config-qualtrics
Advanced tools
eslint-config-qualtrics
These are settings for ESLint used by Qualtrics.
This setup lints your JavaScript code. Check the .eslintrc.js file to see what is included. Feel free to override the rules that make sense for you.
This config assumes that you are using prettier for style-formatting concerns and eslint for code-quality concerns.
In your project folder, run:
npm i -D eslint eslint-config-qualtrics
# or
yarn add -D eslint eslint-config-qualtrics
If you are using typescript then you must add
npm i -D @typescript-eslint/eslint-plugin @typescript-eslint/parser
# or
yarn add -D @typescript-eslint/eslint-plugin @typescript-eslint/parser
If you've installed eslint-config-qualtrics to your project, just set your eslintconfig
(such as the .eslintrc.js
) file to:
module.exports = {
extends: ["qualtrics"],
};
If you are building a react project, then you should extend the qualtrics/react config
module.exports = {
extends: ["qualtrics/react"],
};
Simply add a "rules"
key to your config, then add your overrides and additions there.
For example, to change the react/prop-types
rule to error
, change it to the following
module.exports = {
extends: ["qualtrics"],
rules: {
"react/prop-types": "error",
},
};
FAQs
Qualtrics ESLint config
We found that eslint-config-qualtrics demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.