Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
react-hot-loader-dumb-fork
Advanced tools
This is a stable for daily use in development implementation of React live code editing.
Get inspired by a demo video and try the live demo.
Use one of the starter kits for your next React project.
React Hot Loader was demoed together with Redux at React Europe.
Watch Dan Abramov's talk on Hot Reloading with Time Travel.
npm install --save-dev react-hot-loader
If you want to try hot reloading in a new project, try one of the starter kits, React Hot Boilerplate being the most minimal one.
To use React Hot Loader in an existing project, you need to
These steps are covered by the walkthrough.
If you'd rather stay with Browserify, check out LiveReactload by Matti Lankinen.
Redux is a Flux implementation that supports hot reloading of everything out of the box. Read The Evolution of Flux Frameworks for some context around its creation.
You can use React Hot Loader to tweak a React Native application. Check out react-native-webpack-server by Michael Johnston.
If something doesn't work, in 99% cases it's a configuration issue. A missing option, a wrong path or port. Webpack is very strict about configuration, and the best way to find out what's wrong is to compare your project to an already working setup, such as React Hot Boilerplate, bit by bit. We're also gathering Troubleshooting Recipes so send a PR if you have a lesson to share!
Docs are in a bit of a flux right now because I'm in the process of updating everything to document the major 1.0 release.
If you just learned about React Hot Loader and want to find out more, check out the walkthrough and then try one of the starter kits.
If you've been with us for a while, read 1.0 release notes and migration guide.
Watch the repo to stay tuned!
FAQs
Tweak React components in real time.
We found that react-hot-loader-dumb-fork demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.