
Security News
Another Round of TEA Protocol Spam Floods npm, But It’s Not a Worm
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.
eslint-plugin-sort-decorators
Advanced tools
An ESLint plugin to sort decorators
First, the peer dependencies must be installed:
npm i --save-dev typescript eslint @typescript-eslint/parser
Next, install eslint-plugin-sort-decorators:
npm i --save-dev eslint-plugin-sort-decorators
As this plugin only works with typescript, the parser must be set in a .eslintrc file:
{
"parser": "@typescript-eslint/parser"
}
The plugin can then be activated by adding sort-decorators to the plugins property:
{
"plugins": ["sort-decorators"]
}
The different rules can be defined as follows:
{
"rules": {
"sort-decorators/sort-on-classes": "error"
}
}
Or simply extends a configuration preset:
{
"extends": ["plugin:sort-decorators/recommended"]
}
| Name | Description |
|---|---|
plugin:sort-decorators/recommended | Enables all rules with a warn security level. |
plugin:sort-decorators/strict | Enables all rules with a error security level and autoFix. |
All this configuration can be done on a
overridesection: https://eslint.org/docs/latest/use/configure/configuration-files#how-do-overrides-work
💼 Configurations enabled in.
⚠️ Configurations set to warn in.
✅ Set in the recommended configuration.
🔒 Set in the strict configuration.
🔧 Automatically fixable by the --fix CLI option.
| Name | Description | 💼 | ⚠️ | 🔧 |
|---|---|---|---|---|
| sort-on-accessors | Enforces order of accessors decorators | 🔒 | ✅ | 🔧 |
| sort-on-classes | Enforces order of class decorators | 🔒 | ✅ | 🔧 |
| sort-on-methods | Enforces order of methods decorators | 🔒 | ✅ | 🔧 |
| sort-on-parameters | Enforces order of parameters decorators | 🔒 | ✅ | 🔧 |
| sort-on-properties | Enforces order of properties decorators | 🔒 | ✅ | 🔧 |
See information about breaking changes and release notes here.
FAQs
An ESLint plugin to sort decorators
We found that eslint-plugin-sort-decorators demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.

Security News
PyPI adds Trusted Publishing support for GitLab Self-Managed as adoption reaches 25% of uploads

Research
/Security News
A malicious Chrome extension posing as an Ethereum wallet steals seed phrases by encoding them into Sui transactions, enabling full wallet takeover.