Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
notifications-panel
Advanced tools
Note This module is no longer being developed – its functionality has been rolled into Calypso. This module should no longer be used.
This repository contains the React component which displays WordPress.com notifications and provides for management of those notifications.
<NotificationsPanel { ...{
isVisible,
locale,
wpcom
} } />
The following sections describe what is required in order to locally develop this application.
When developing the app locally we need to fake its base URL because of the way that user authentication works.
The OAuth application will only respond to a select number of domain origins.
Thus the following line will need to exist in your local /etc/hosts
file.
The app will be served at this address when running the development server.
127.0.0.1 notifications.localhost
After setting up the local domain mapping install the application with the following sequence of commands:
git clone git@github.com:Automattic/notifications-panel.git
cd notifications-panel
npm install
With the code and dependent libraries installed run the development server with the following command:
npm start
After it boots up load the entry at notifications.localhost:8888 in your browser.
FAQs
The core notifications panel for WordPress.com notifications
The npm package notifications-panel receives a total of 3 weekly downloads. As such, notifications-panel popularity was classified as not popular.
We found that notifications-panel demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.