data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
[data:image/s3,"s3://crabby-images/9beda/9beda3ab5d4f6abb88eb32ce2637b16b9502247e" alt="Build Status"](https://travis-ci.org/jedirandy/redux-url) [data:image/s3,"s3://crabby-images/23e6e/23e6e8ce10852eea56df788b87910673a317110e" alt="npm module"](https://www.npmjs.org/package/redux-url)
A redux middleware for synchronizing the url with your redux store's state. It provides a set of action creators for changing the url, and if the url matches a user-defined route, an action will be dispatched, provided with information such as parameters and query.
npm install --save redux-url
Note that history
is needed for it to work correctly.
import createHistory from 'history/createBrowserHistory'; // choose a history implementation
import { createStore, applyMiddleware } from 'redux';
import { createRouter, navigate } from 'redux-url';
const routes = {
'/': 'HOME', // when url is matched, will dispatch an action of type 'HOME', the payload contains matched params and query
'/todos/:id': ({ id }, query) => ({ type: 'CHANGE_TODO', payload: id, query }), // you can also pass a function to transform the action, the matched params, query and the original path will be passed in
'*': 'NOT_FOUND'
};
const router = createRouter(routes, createHistory());
const store = createStore(
reducer,
applyMiddleware(router)
);
store.dispatch(navigate(location.pathname, true)); // In order to restore the state from the URL when refreshed
store.dispatch(navigate('/todos/123')); // navigate to '/todos/123'
createRouter(routes, history)
:
creates the middleware
arguments
routes (object) : The URL patterns to be mapped, where values can be either of the following:
string:
when the URL matches the route, an action will be dispatched of which the type is the given string, and the payload has the following shape:
{
type: string,
payload: {
params: Object,
query: Object,
path: string
}
}
function: (object, object, string) => Action
a function that takes the matched params
, query
and the original path
, returns an action
history: the history object created from lib history
,
such as createBrowserHistory
returns
the middleware
navigate(path: string, replace: boolean = false)
:
creates an action for navigating to the path, replace
indicates whether it should modify the current history entry rather than push a new one
push(path: string)
:
a shorthand of navigate(path, false)
replace(path, string)
:
a shorthand of navigate(path, true)
goBack()
:
creates an action for going back
goForward()
:
creates an action for going forward
go(n: number)
:
creates an action for going n (can be negative) steps
FAQs
[data:image/s3,"s3://crabby-images/9beda/9beda3ab5d4f6abb88eb32ce2637b16b9502247e" alt="Build Status"](https://travis-ci.org/jedirandy/redux-url) [data:image/s3,"s3://crabby-images/23e6e/23e6e8ce10852eea56df788b87910673a317110e" alt="npm module"](https://www.npmjs.org/package/redux-url)
The npm package redux-url receives a total of 356 weekly downloads. As such, redux-url popularity was classified as not popular.
We found that redux-url demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.