Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
requirejs-react-jsx
Advanced tools
A RequireJS plugin for compiling React JSX files. Will use react-tools when compiling using r.js
, and will use JSXTransformer
or Babel when running in the browser in development. This allows us to support multiple bundles in r.js
and exclude the JSXTransformer
from all of them since we're requiring it dynamically and not explicitly. This also means that we can get 1:1
Source Maps in both development and production.
$ bower install requirejs-react-jsx --save
If you're not using bower to manage your dependencies (you should), you can just download the jsx.js file manually.
Since we're also using react-tools for the build step while running in a node process, and not in the browser, you will need to install that also:
$ npm install react-tools --save
app.jsx
define(function(require){
var React = require('react');
function App() {
this.AppView = React.createClass({
render: function () {
return (
<div>
<p>Hello, React!</p>
</div>
);
}
});
}
App.prototype.init = function () {
React.render(<this.AppView />, document.body);
};
return App;
});
main.js
require.config({
paths: {
"react": "bower_components/react/react-with-addons",
"babel": "bower_components/requirejs-react-jsx/babel-5.8.34.min",
"jsx": "bower_components/requirejs-react-jsx/jsx",
"text": "bower_components/requirejs-text/text"
},
shim : {
"react": {
"exports": "React"
}
},
config: {
babel: {
sourceMaps: "inline", // One of [false, 'inline', 'both']. See https://babeljs.io/docs/usage/options/
fileExtension: ".jsx" // Can be set to anything, like .es6 or .js. Defaults to .jsx
}
}
});
require(['jsx!app'], function(App){
var app = new App();
app.init();
});
Call with $ node bower_components/r.js/dist/r.js -o build.js
In your r.js build.js
config:
// add `optimize=none` to skip script optimization (useful during debugging).
({
appDir: "./",
baseUrl: "./",
dir: "./compiled",
mainConfigFile: "./main.js",
optimize: "uglify2",
skipDirOptimize: true,
generateSourceMaps: true,
findNestedDependencies: true,
preserveLicenseComments: false,
onBuildWrite: function (moduleName, path, singleContents) {
return singleContents.replace(/jsx!/g, '');
},
modules: [
{
name: "main",
exclude: ['jsx']
}
]
})
If you want code coverage with Istanbul you will have to do a little extra work. Istanbul only instruments code required by nodes require
function by default. However, you can make Istanbul also instrument RequireJS loaded dependencies in a node environment by adding the --hook-run-in-context
switch.
requirejs-react-jsx will automatically detect that it is being run in an Istanbul enabled environment and
The --hook-run-in-context
only makes Istanbul pick up normally loaded RequireJS files though, and not the ones transformed by RequireJS plugins. So requirejs-react-jsx will automatically detect that it is being run in an Istanbul enabled environment and manually instrument the transpiled code so Istanbul can collect coverage.
A full example of a coverage script in package.json
could look like this:
{
"scripts": {
"test": "mocha",
"coverage": "istanbul cover --hook-run-in-context _mocha"
}
}
1.0 - Eliminated all other transformer options than Babel. Switched config variable from jsx
to babel
. Added browser compatible babel 5.x build to repository to use for in-browser compilations
FAQs
A RequireJS plugin for loading jsx in require.js and r.js
The npm package requirejs-react-jsx receives a total of 230 weekly downloads. As such, requirejs-react-jsx popularity was classified as not popular.
We found that requirejs-react-jsx demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.