Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
lerna-script-preset-wix-npm
Advanced tools
A preset for wix npm-based repos that exposes following tasks:
node_modules
, target
, *.log
...;origin/master
;.nvmrc
from root of repo to all modules, module versions, package.json
docs/repo links, etc.Given you have non-lerna project, install needed modules:
npm install --save-dev lerna lerna-script lerna-script-preset-wix-npm husky
init lerna:
node_modules/.bin/lerna init
add lerna.js to root of repo like:
module.exports = require('lerna-script-preset-wix-npm')();
setup your package.json
{
"name": "aggregator",
"private": true,
"version": "1.0.0",
"scripts": {
"prepush": "lerna-script sync",
"postinstall": "lerna bootstrap",
"clean": "lerna-script clean",
"test": "lerna-script test",
"ls": "lerna-script",
"idea": "lerna-script idea"
},
"devDependencies": {
"husky": "^0.14.3",
"lerna": "^2.0.0",
"lerna-script": "latest",
"lerna-script-preset-wix-npm": "latest"
}
}
Then:
prepush
task will be executed by husky
and all sync actions will be performed;ls
- run misc preset tasks like npm run ls deps:latest
.If preset almost works for you, you can reuse most of it but customize a selected task, like:
const preset = require('lerna-script-preset-wix-npm')();
function clean(log) {
preset.clean(log).then(() => {
//do your thing
});
}
module.exports = {
...preset,
clean
}
FAQs
preset for wix npm projects
We found that lerna-script-preset-wix-npm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.