Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
jscs-config-seegno
Advanced tools
Seegno-flavored JSCS config.
$ npm install jscs jscs-config-seegno should --save-dev
Create an .jscsrc
file with the following:
preset: seegno
Add the following script
to your package.json
:
{
"scripts": {
"lint": "jscs ."
}
}
and run the linter with:
$ npm run lint
The preset includes the following list of custom rules.
disallowGeneratorsInDescribeFunctions
Disallows the usage of generators for the describe
grouping primitive that features in testing frameworks such as mocha
.
This rule helps to avoid incorrectly replacing the function signature with a generator declaration, which results in some cryptic errors when running the tests, since describe
is not meant to be asynchronous.
Requires: mocha
Type: Boolean
Value: true
disallowGeneratorsInDescribeFunctions: true
describe('foobar', function () {
it('should work');
});
describe('foobar', function *() {
it('should work');
});
disallowOnlyFilterInTestFunctions
Disallows the usage of only
for grouping primitives or test cases in mocha
.
Although it might help to run individual tests locally, this rule helps to ensure the entire test suite runs, for instance, using build or pre-commit scripts.
Requires: mocha
Type: Boolean
Value: true
disallowOnlyFilterInTestFunctions: true
describe('foobar', function () {
it('should work');
});
describe.only('foobar', function *() {
it('should work');
});
describe('foobar', function *() {
it.only('should work');
});
requireShouldAssertionExecution
Disallows the usage of test expectation properties in favor of methods with libraries such as should
.
Due to the nature of some expectation libraries, it's easy to forget a method ()
which might result in an assertion that never gets executed. This rule is meant to avoid that issue.
Requires: should
Type: Boolean
Value: true
requireShouldAssertionExecution: true
true.should.be.true();
true.should.be.true;
requireSqlTemplate
Disallows the usage of raw SQL templates with interpolation.
This rule enforces the usage of a library such as sql-tag, which escapes data provided to an SQL query statement via interpolation, helping to avoid, for instance, potential injection attacks.
Requires: sql-tag
Type: Boolean
Value: true
requireSqlTemplate: true
const column = '*';
const query = sql`SELECT ${column} FROM foobar`;
fn(sql`SELECT ${column} FROM foobar`)
const column = '*';
const query = `SELECT ${column} FROM foobar`;
fn(`SELECT ${column} FROM foobar`)
2.0.0 (2016-03-31)
Merged pull requests:
typeof
#16 (ruiquelhas)requireSqlTemplateInQueryFunction
rule #14 (ruiquelhas)FAQs
Seegno-flavored JSCS config.
We found that jscs-config-seegno demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.