Security News
The Risks of Misguided Research in Supply Chain Security
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
js-import-sort
Advanced tools
A JS codemod to sort imports
Built on top of facebook/jscodeshift
This will transform a JS file, sorting and organising its imports (ES2015/ES6).
Example:
import Main from 'aaaa';
import {ZMain} from 'aaaa';
import First from 'zzz';
import {Third} from 'zzz';
import {Second} from 'zzz';
import * as someDefault from 'bbb';
import {a as b} from 'packageModule';
import SomeClass from './MyModule';
import AnotherClass from '../../Module1';
import * as util from 'util';
Becomes:
import * as util from 'util';
import Main, {ZMain} from 'aaaa';
import * as someDefault from 'bbb';
import First, {Second, Third} from 'zzz';
import {a as b} from 'packageModule';
import AnotherClass from '../../Module1';
import SomeClass from './MyModule';
Imports are separated by node, dependencies and devDependencies in package.json
, other, and relative imports.
To run, just run:
js-import-sort --path ./*
You can remove the the blank lines between imports by passing --no-blank-lines
to the command.
js-import-sort
supports 3 of the debugging tools from jscodesift, dry
, print
and verbose
which can be used in any combination
use --dry
and --print
to view the results of the changes before they are applied
FAQs
A jS Codemode to sort/organise imports
The npm package js-import-sort receives a total of 42 weekly downloads. As such, js-import-sort popularity was classified as not popular.
We found that js-import-sort demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.