Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
react-searchkit
Advanced tools
React-SearchKit is a React library that allows you to build in an easy way your search application.
Main features:
You can find a collection of examples in the src/demos
folder:
Install dependencies and run the React app to try them out (see steps below).
To run the Elasticsearch backend for the demo, you can use Docker. A docker-compose
file with ES 7
and nginx
as reverse proxy is available and ready to use.
Run the services:
cd src/demos/elasticsearch/docker
docker-compose up
Then, init the demo data:
curl -XPUT 'http://localhost:9200/random?pretty' -H 'Content-Type: application/json' -d @es7-mappings.json
curl -XPOST 'http://localhost:9200/random/_bulk' -H 'Content-Type: application/json' --data-binary @es-random-data.json
curl -XGET 'http://localhost:9200/random/_count?pretty'
Demo data have been randomly generated using https://next.json-generator.com.
In case you want to clear your elastic search from data you can use
curl -X DELETE 'http://localhost:9200/_all'
React-SearchKit uses create-react-app as development toolkit.
Install the library:
npm install
Start the demo application:
npm start
The library uses Jest as test runner. To run the tests:
npm test
The library uses rollup
to build a final version inside the /dist
folder and it will build CommonJS and ES Modules versions:
npm run build
FAQs
React components to build your search UI application
We found that react-searchkit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.