
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
eslint-plugin-no-use-extend-native
Advanced tools
ESLint plugin to prevent use of extended native objects
ESLint plugin to prevent use of extended native objects
Uses Sindre Sorhus's proto-props
First, install ESLint via
npm install --save-dev eslint
Then install eslint-plugin-no-use-extend-native
npm install --save-dev eslint-plugin-no-use-extend-native
In your .eslintrc
file add the plugin as such:
{
plugins: [
'no-use-extend-native'
]
}
To modify the single rule, no-use-extend-native
, add the rule to your .eslintrc
as such:
{
plugins: [
'no-use-extend-native'
],
rules: {
'no-use-extend-native/no-use-extend-native': 0
}
}
The default value is 2
.
With this plugin enabled, ESLint will find issues with using extended native objects:
var colors = require('colors');
console.log('unicorn'.green);
// => ESLint will give an error stating 'Avoid using extended native objects'
[].customFunction();
// => ESLint will give an error stating 'Avoid using extended native objects'
More examples can be seen in the tests.
MIT © Dustin Specker
FAQs
ESLint plugin to prevent use of extended native objects
The npm package eslint-plugin-no-use-extend-native receives a total of 92,232 weekly downloads. As such, eslint-plugin-no-use-extend-native popularity was classified as popular.
We found that eslint-plugin-no-use-extend-native demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.