Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
gulp-rewrite-flowtyped-modules
Advanced tools
A flow-syntax-aware module dependency rewriter gulp plugin.
Uses flow-parser
to scan the
potentially-flow-typed JavaScript AST file for import
and require
statements.
It rewrites modules according to the options passed in.
This behaves very similar to the
rewrite-module
in babel-preset-fbjs from the
fbjs package. The difference here is that
it isn't done through Babel, but through flow-parser
, and therefore keeps flow types intact.
prefix
: Module prefix to prepend to all rewritten modules. (defaults to './'
)
map
: moduleMap to use for rewriting modules (empty by default)
flow
: options to pass to flow-parser
. See https://www.npmjs.com/package/flow-parser#options
FAQs
A flow-syntax-aware module dependency rewriter gulp plugin.
The npm package gulp-rewrite-flowtyped-modules receives a total of 1 weekly downloads. As such, gulp-rewrite-flowtyped-modules popularity was classified as not popular.
We found that gulp-rewrite-flowtyped-modules demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.