
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
mycoolbutton
Advanced tools
This is the complete example for this guide on publishing your React component to npm
Replace contents in /src with your React component.
Edit webpack.config.js, replace the following:
entry: './src/YOUR_COMPONENT.js' Replace value of entry to path to the entry point of your component.output.filename to the name of your component output: {
path: path.resolve('lib'),
filename: 'YOUR_COMPONENT.js',
libraryTarget: 'commonjs2',
},
Edit package.json, replace the following:
"name": "YOUR_PACKAGE_NAME" Replace the value of name to your package name. This will be the name of the package that is published to npm and the name that is used when other people install your package using npm install YOUR_PACKAGE_NAME.version and description to accordingly."main": "./lib/YOUR_COMPONENT.js" replace YOUR_COMPONENT.js with the name that you've set in output.filename during Step #2peerDependencies list.Building your component by running npm build in your command line. This would generate the folder /lib which includes your component.
Publishing to npm
npm login in your command line, and enter your credentials.npm publish, and your React component will be uploaded to npm! You can find it at https://www.npmjs.com/package/[YOUR PACKAGE NAME] or your npm profile.To update your package, make sure you remember to increment the version in package.json, and then perform Step #5 again.
FAQs
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.